Swiss Government SharePoint Breach Compromised 200 Accounts

BIT's SharePoint intrusion compromised credentials for about 200 Swiss federal accounts, likely via Microsoft flaws fixed in the July Patch Tuesday updates.
Table of Contents
    Add a header to begin generating the table of contents

    Switzerland’s Federal Office for Information Technology and Telecommunication (BIT) has disclosed a network intrusion that compromised login credentials for roughly 200 accounts on its federal SharePoint platform. The office detected unusual activity on its SharePoint servers on July 28 and, after security specialists reviewed the system on July 31, found that credentials for several accounts had been stolen. BIT has not stated which flaw the attackers used, and no ransomware or data extortion group has claimed responsibility.

    The SharePoint Vulnerability Chain BIT Is Investigating

    BIT believes the attackers exploited SharePoint vulnerabilities disclosed by Microsoft in mid-July and fixed in the July 2026 Patch Tuesday updates. The office named two candidate flaws: CVE-2026-56164, an actively exploited SharePoint privilege escalation vulnerability, and CVE-2026-50522, a critical remote code execution flaw that was later exploited to steal SharePoint machine keys and maintain access after patching. BIT has not confirmed which of the two was used in the intrusion.

    The Account Scope and the Absence of Demonstrated Data Theft

    Approximately 200 accounts were affected. BIT said confidential information and particularly sensitive personal data are not permitted to be stored on the affected SharePoint platform, and it has found no evidence that data was stolen beyond the compromised login credentials. Because the platform’s contents are limited by policy, the assessed exposure is confined to credential compromise rather than exfiltration of sensitive records.

    How BIT Contained the SharePoint Intrusion

    The federal IT office moved quickly on containment: it blocked external internet access to the SharePoint servers, patched the suspected vulnerabilities, reset the passwords on affected accounts, and began reinstalling the compromised servers. Federal employees are using alternative sharing methods until the remediation work is complete, while BIT investigates with the Swiss Federal Office for Cyber Security and Microsoft.

    Why a Federal Collaboration Platform Is a High-Value Government Target

    A successful intrusion into a national government’s collaboration platform carries political and supply-chain risk even when it stops at credential compromise, because SharePoint accounts are routinely tied to federal identity systems and shared documents. The incident also shows that a flaw addressed in a routine monthly patch batch can still yield a working intrusion if the fix is not deployed before attackers reach the environment. For other SharePoint deployments, the practical action is to verify that the July Patch Tuesday fixes for CVE-2026-56164 and CVE-2026-50522 are applied and to review sign-in and key-management telemetry for the machine-key theft pattern the second flaw enables.

    The Swiss case shows that containment speed matters as much as patch coverage: BIT detected the activity on July 28, confirmed credential compromise as the investigation progressed, ordered external access blocked, and reset passwords within days. That sequence limited a government-account intrusion to the credential layer and is the standard against which other SharePoint deployments will be measured as the investigation into which flaw opened the door continues. The distinction between a single account compromise and full-tenant takeover also matters for federal planners: the ability to steal machine keys, which the second candidate vulnerability is associated with, is what converts a short credential pass into long-lived persistence. Until analysts confirm which flaw was used, federal security teams should assume the worst and treat every related SharePoint account as potentially exposed.

    The incident also highlights how reliant public-sector bodies have become on a single commercial collaboration product, and how much of that reliance is invisible to the organizations that use it. The fact that roughly 200 accounts were compromised in a government tenant before the activity drew a specialist review is a signal that even well-resourced federal IT operations struggle to detect credential abuse inside a collaboration platform when the indicators are subtle. For other national administrations that run SharePoint at scale, the Swiss disclosure is a practical checklist item: confirm the July Patch Tuesday fixes are present, review where machine keys are stored, and verify that accounts with administrative or elevated rights are subject to the same monitoring as those of regular users.

    Related Posts